Last updated: August 2026 · Draft — not yet reviewed by legal counsel.
Takeyard (“we,” “us”) respects your privacy. This policy explains what data we collect, how we use it, and your rights. We are based in Denmark and comply with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the Danish Data Protection Act (Databeskyttelsesloven, Act No. 502 of 23 May 2018).
1. Data controller
The data controller is Takeyard, operated from Denmark, EU. For all privacy inquiries, contact us at bastianbjw@gmail.com.
The Danish Data Protection Agency (Datatilsynet) is our supervisory authority. You can contact them at datatilsynet.dk if you have concerns about how we handle your data.
2. What data we collect
Account data
- Email address — used for authentication and account recovery.
- Display name — shown to other users on your profile and in projects.
- Roles and genres — your selected creative roles and music genres.
- Avatar image — if you upload one.
Content you create
- Project data — titles, descriptions, calls, and answers you post.
- Uploaded files — audio stems, beats, artwork, and other files you share in project workspaces.
- Reviews — ratings and written feedback you submit.
Proof data
- File fingerprints — SHA-256 hashes of files you upload, calculated in your browser.
- OpenTimestamps proofs — cryptographic attestations anchoring your fingerprints to the Bitcoin blockchain.
- Ledger entries — permanent records of your activity (uploads, joins, project creation).
Technical data
- Authentication tokens — managed by Supabase Auth for session management.
- Browser cookies — see our Cookie Policy.
- Private media access log — when a link is issued for a file inside a project workspace, we record who requested it, which file, and when. This is a security measure: if unreleased material appears where it should not, the project owner can see who had access. Visible only to the owner of that project.
We do not collect IP addresses for tracking, browsing history, or device fingerprints, and we use no third-party analytics or tracking tools of any kind.
Activity signal (beta)
To learn how to suggest collaborators worth your time, we record four things while Takeyard is in beta:
- Calls you open — including the ones you decide not to answer.
- Profiles you open.
- Searches that return nothing — the search text, role and genre.
- Board filters you apply — which role and genre.
Each record is your account ID, what kind of thing it was, which item, and the time. Nothing more. Specifically: no cookies or other identifiers stored on your device, no IP addresses, no user agents, no device or browser fingerprints, and no third parties — this data is written to our own database and never leaves it. Because nothing is stored on or read from your device, no cookie consent banner is required; because it is still personal data, everything below applies to it.
You can turn it off at any time from Account settings, and delete everything already recorded, without affecting anything else about your account. It is included in your data export, and it is deleted automatically after 180 days.
Reports and blocks
- Reports you file — what you reported, the reason, and any detail you wrote. Reports are not shown to the person reported, and we do not tell them who filed one.
- People you block — visible only to you. The person blocked is not notified.
3. Legal basis for processing (GDPR Article 6)
- Contract performance (Art. 6(1)(b)) — processing your account data, project data, and uploaded files is necessary to provide the service you signed up for.
- Legitimate interest (Art. 6(1)(f)) — permanent retention of ledger entries and contribution evidence serves the legitimate interest of maintaining verifiable proof of creative activity. This is a core feature of the Platform that you are informed about before your first upload.
- Legitimate interest (Art. 6(1)(f)) — the activity signal described above, to build collaborator suggestions, and the private media access log, to protect unreleased material. Both are limited to what that purpose needs, and you can object to the activity signal at any time by switching it off in Account settings, which is the Art. 21 right to object exercised directly rather than by request.
- Legitimate interest (Art. 6(1)(f)) — reports and blocks, to keep the platform usable and its users safe.
- Consent (Art. 6(1)(a)) — where required, such as for non-essential cookies (we do not currently use any).
4. How we use your data
- To provide the service — storing and displaying your content, managing project memberships, generating proofs.
- To authenticate you — verifying your identity when you sign in.
- To communicate with you — sending essential service emails (account recovery, security notices, changes to Terms).
- To suggest collaborators — using the activity signal described in Section 2, during the beta.
- To keep the platform safe — reviewing reports, and investigating unauthorised access to private files.
We do not sell your data, we do not use it for advertising, and we do not share it with third parties except as described below.
Suggesting collaborators means analysing your activity to rank what you see, which is profiling in the sense GDPR uses the word — so we say so rather than claiming otherwise. It is not automated decision-making under Art. 22: nothing is decided about you without a human, and a suggestion has no legal or similarly significant effect. You can switch it off in Account settings.
5. How your data is stored
Your data is stored on Supabase, which uses cloud infrastructure with encryption at rest and in transit. Our database uses row-level security policies that enforce access control at the database level — you can only access data you are authorized to see.
Uploaded files are stored in Supabase Storage with the same access controls. Evidence copies in the contributions bucket are readable only by you and cannot be deleted while your account is open — not even by you. That is deliberate: evidence you could quietly remove mid-collaboration would not be evidence. They are deleted if you close your account.
6. Third-party services & data transfers
- Supabase — database, authentication, and file storage. Data may be processed in the EU or US. Supabase provides Standard Contractual Clauses (SCCs) for transfers outside the EU/EEA.
- OpenTimestamps — a free, open-source, decentralized network for timestamping. We send only file fingerprints (hashes), never the files themselves. Fingerprints are not personal data.
- Vercel — hosting for the web application (when deployed). Vercel provides data processing agreements compliant with GDPR.
Where data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place as required by GDPR Chapter V (Standard Contractual Clauses or adequacy decisions).
7. Your rights under GDPR
You have the right to:
- Access (Art. 15) — request a copy of the personal data we hold about you.
- Rectification (Art. 16) — ask us to correct inaccurate data.
- Erasure (Art. 17) — ask us to delete your personal data (see limitations below).
- Restriction (Art. 18) — ask us to limit how we process your data.
- Portability (Art. 20) — receive your data in a machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interests.
- Complaint — lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or your local supervisory authority.
You can exercise the two most important rights yourself, immediately, from Account settings: Download my data produces a machine-readable JSON export of everything you have added, including your full proof ledger; Delete my account erases your account as described below. For anything else, email bastianbjw@gmail.com and we will respond within 30 days as required by the GDPR.
What deletion actually does. We keep only what protects someone other than you, and erase the rest:
- Erased: your profile, name, email, avatar, bio, links and portfolio. Messages you wrote are removed from conversations. Your private evidence copies in the contributions storage are deleted. Projects you own that have no other members are deleted, including their files. Your activity signal and everyone you had blocked are deleted.
- Transferred: projects you own that others are working in pass to the longest-standing member, so their work is not destroyed by your leaving.
- Retained, without your identity:your ledger entries — a file fingerprint, a timestamp and a project title. Your name is replaced with “Former member”. These stay because your collaborators’ credits are evidenced by them: deleting your row would erase their proof of who they worked with.
Legal basis for that retention: GDPR Art. 17(3)(e) — processing necessary for the establishment, exercise or defence of legal claims. That exemption is deliberately narrow, so we apply it only to the minimum that serves other people, and pseudonymise everything around it. You are told this before your first upload, and again in the deletion confirmation, which states exactly how many projects and proof records your own account will be affected in.
8. Data retention
- Account data — retained while your account is active. Erased immediately when you delete your account.
- Project data — retained while the project exists. Projects with no other members are deleted with your account; projects with collaborators are transferred to them.
- Messages and free text you wrote — erased when you delete your account.
- Contribution evidence files — readable only by you, so they are deleted when you delete your account. Once you leave they protect nobody, and retaining them would not be necessary.
- Ledger entries — retained permanently and insert-only: a fingerprint, a timestamp and a project title, pseudonymised on account deletion. Legal basis: Art. 17(3)(e), establishment and defence of legal claims — they evidence your collaborators’ credits as well as your own.
- OpenTimestamps proofs — retained permanently as part of ledger entries. These are also published to the public OpenTimestamps calendar network and anchored into the Bitcoin blockchain, which we cannot alter or withdraw. They contain a cryptographic hash only — never your file, your name or any personal data.
- Activity signal — deleted automatically after 180 days, or immediately whenever you ask, from Account settings. Deleted with your account.
- Private media access log — retained for 12 months. Its whole purpose is answering “who had this file” after a leak, which is a question that is usually asked late.
- Reports — retained while open, and for 12 months after they are resolved, so a later decision about the same person can be made in light of the earlier one. Reports you filed are kept if you delete your account: a report is a record about its subject as much as about you, and spotting a pattern depends on knowing that several came from different people. Your name is replaced with “Former member” along with the rest of your profile.
- Blocks — deleted when you unblock the person, and deleted with your account.
Reviews you wrote about other people’s work are kept, attributed to “Former member”. They are feedback the recipient relies on and describe their work rather than you.
9. Security
We implement appropriate technical and organisational measures as required by GDPR Article 32, including: row-level security at the database level, HTTPS for all connections, encryption at rest and in transit, secure session management, and client-side file hashing (your files are not sent to any third party for fingerprinting).
10. Children
Takeyard is not intended for children under 13, which is the age of digital consent in Denmark under the Danish Data Protection Act (Section 6a). We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, please contact us and we will delete it promptly.
11. International users
If you use Takeyard from outside the EU/EEA, your data is transferred to and processed in the EU. We do not transfer your personal data outside the EU/EEA unless appropriate safeguards are in place (see Section 6).
12. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email at least 30 days before taking effect.
13. Contact & supervisory authority
Data controller: Takeyard, based in Denmark, EU.
Email: bastianbjw@gmail.com
Supervisory authority: Datatilsynet (Danish Data Protection Agency)
Website: datatilsynet.dk
Email: dt@datatilsynet.dk